Kiteworks lifts shutdown order after incident-free weekend
Managed file switch (MFT) companies supplier Kiteworks has rescinded a brief shutdown suggestion asking its prospects to show off their home equipment for six hours on the morning of Saturday 26 September, after no safety incidents occurred.
In a press release revealed on Sunday 27 September, the corporate stated its suggestion was lifted for all prospects and it was now protected to carry their techniques again on-line.
The agency stated that every one “identified” vulnerabilities had been addressed within the present launch, and that there remained no indication of any system compromises, both at Kiteworks itself, or throughout its buyer base.
Kiteworks chief info safety officer Frank Balonis stated: “Kiteworks acquired credible menace intelligence from federal intelligence authorities indicating {that a} menace actor could try to focus on some Kiteworks techniques.
“Out of an abundance of warning, we notified prospects immediately and beneficial a precautionary shutdown window whereas we proceed to work via the matter with federal intelligence authorities,” stated Balonis.
“We have now no indication that Kiteworks or our prospects’ techniques have been compromised, so this advisory is preventative slightly than a response to a confirmed breach,” he reiterated.
“Kiteworks has accounted for all identified vulnerabilities in our present launch, 9.5.1, and we proceed to suggest prospects run the most recent model.”
The transient shutdown affected prospects who self-managed their Kiteworks techniques, both on-premise or by way of their Amazon Net Providers (AWS) or Azure environments.
Laptop Weekly understands that Kiteworks pulled the plug itself on techniques that it hosts on behalf of its prospects throughout the identical window – 2am to 8am GMT (3am to 9am BST) – all home equipment run as a part of such a managed service at the moment are additionally again on-line and working usually.
On the time of writing, the menace just isn’t thought to have affected some other Kiteworks subsidiaries, comparable to Zivver, Dracoon, totemo, ownCloud, Wamnet, Maytech, Bonfy.ai, or 123FormBuilder.
Uncommon transfer
The highly-unusual suggestion to close down probably weak home equipment got here amid hypothesis that an as-yet undisclosed zero-day was being exploited within the wild, probably by a ransomware gang.
Since MFT services and products are notably helpful targets for menace actors, who use them to conduct large-scale provide chain cyber assaults on a number of downstream customers, the advice was not essentially with out benefit.
Certainly, Kiteworks, which was previously referred to as Accellion previous to a 2021 rebrand, has been on the receiving finish of such cyber assaults earlier than
A 2021 incident noticed high-profile prospects together with aviation specialist Bombardier, cyber agency Qualys, fossil gasoline big Shell, and telco Singtel focused, amongst others.
Nevertheless, in response to an e-mail to prospects, posted to Reddit, Kiteworks hinted its core MFT product was unaffected by the difficulty, which seems to have existed solely in its Superior Kinds product.
Also called Safe Information Kinds, the Superior Kinds product is a comparatively current introduction to the corporate’s portfolio and is in use at solely a restricted subset of shoppers – a lot of them organisations required to adjust to US authorities FedRAMP requirements.
In response to the shopper e-mail, these organisations have been receiving direct steerage from Kiteworks via an prolonged shutdown course of.

